git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 0/4] faster SHA-1 collision detection

From
Junio C Hamano <gitster@pobox.com>
Date
Oct 9, 2026, 23:41 UTC
Message-ID
<xmqq7bjqjvbi.fsf@gitster.g>
In-Reply-To
<CALnO6CBbtKomawqc81MPV5Ngtc9J3M1ej4enGD3ZUzWnPSfsgw@mail.gmail.com>
"D. Ben Knoble" <ben.knoble@gmail.com> writes:
Show 23 quoted lines
> The sha1collisiondetection submodule and the sha1dc code (extracted
> from that submodule's upstream, if I'm reading 28dc98e343 (sha1dc: add
> collision-detecting sha1 implementation, 2017-03-16) correctly?) are
> MIT licensed, too, so there is some precedent for Git here. I skimmed
> what I could find of the original threads:
>
> - https://lore.kernel.org/git/20170223195753.ppsat2gwd3jq22by@sigill.intra.peff.net/
> - https://lore.kernel.org/git/?q=sha1dc%3A+add+collision-detecting+sha1+implementation
>
> but I didn't see a discussion of licensing at that time. Perhaps the
> idea is that we are clear that such code carries a different license
> from Git?
>
> Anyway, I suppose the fair thing would then be for Scott's code to be
> MIT (and/or Apache2), in which case it would need similar
> clarifications? (Or are we prepared to take the stance that de nouveau
> code based on existing code can be license-washed, in this case to
> GPL-2?)
>
> Interestingly, Gentoo claims Git's license is only GPL-2, but I think
> they compile in the sha1dc code since it's the default in meson.
> Should we be claiming the Git package (with sha1dc) is actually GPL-2
> and MIT?

In the abov, Gentoo's mention is about "Git package" as a whole. Git package as a whole can be distributed under GPLv2 only.

MIT, BSD-2 or BSD-3 are permissive and essentially says "you can do whatever you want with the code (including combining with other code or making it proprietary), as long as you keep our copyright notice, keep our disclaimer, and (in the case of BSD-3) do not use our names for endorsement". Specifically, they do not forbid us from incorporating their ware into our project that is licensed differently, as long as we honor their licensing terms on the source files we got from them.

Because we have mixed "permissive" code into GPLv2 code to form a single "work based on the Program", GPLv2 Section 2(b) dictates that the entire combined work must be distributed under the terms of the GPLv2 (and again, the permissiveness of "other" licenses is what allows us to do so). You cannot distribute the finished binary or the combined sources under a permissive license, because doing so would violate the GPLv2's copyleft requirement.

The original "permissively licensed" files (and any modifications made purely to those files) still maintain their original copyright headers and original "permissive" license text. This is because the original copyright holder of the code granted a license to use their files under the original "permissive" licensing terms, which requires us to keep their copyright notice. We do not own the copyright to the original "permissive" code. We are only licensed to use them. So we have no legal authority to strip these "permissive" licenses or unilaterally "relicense" those files into GPLv2.

So to answer your question in the last sentence, we should say "Git package as a whole is GPLv2 only, but parts are borrowed from copyright holders who licensed them under different terms, and these parts can be used under these different parts. For example, sha1dc can be copied from our source tree to your non GPLv2 project as long as you honor their MIT license".

Previous: Todd ZullingerNext: Junio C Hamano
Message 20 of 21 in “faster SHA-1 collision detection”
  1. 0/4 faster SHA-1 collision detectionScott Chacon, Sep 29, 2026
  2. 1/4 sha1dc-accel: add a block loop for sha1dc's SHA1_CTXScott Chacon, Sep 29, 2026
  3. Johannes SchindelinOct 7, 2026
  4. 2/4 sha1dc-accel: vectorize the unavoidable-bitconditions checkScott Chacon, Sep 29, 2026
  5. Johannes SchindelinOct 7, 2026
  6. Junio C HamanoOct 7, 2026
  7. 3/4 sha1dc-accel: compress with SHA-NI on x86-64Scott Chacon, Sep 29, 2026
  8. 4/4 sha1dc-accel: compress with the ARMv8 SHA-1 instructionsScott Chacon, Sep 29, 2026
  9. Johannes SchindelinOct 7, 2026
  10. Junio C HamanoOct 7, 2026
  11. Scott ChaconOct 7, 2026
  12. Sebastian ThielOct 8, 2026
  13. Sam ReisOct 8, 2026
  14. D. Ben KnobleOct 8, 2026
  15. Sam ReisOct 8, 2026
  16. Junio C HamanoOct 8, 2026
  17. D. Ben KnobleOct 8, 2026
  18. Junio C HamanoOct 8, 2026
  19. Todd ZullingerOct 9, 2026
  20. Junio C HamanoOct 9, 2026
  21. Junio C HamanoOct 8, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.